Expand description
Minimal Linux-first mesh underlay slice (design tips 5–6).
Not a WireGuard daemon product. Provides:
- peer dial/accept role lock (C2+node DialOrAccept; HQ DialOnly)
- userspace UDP + AEAD path on Linux (encrypted pipe)
- separate authorization token barrier for probe actions (transport crypto ≠ authorization)
- clear refuse on Win/mac and for HQ underlay accept
- tip 6: TCP bridge-reach over underlay (HTTP+WS dialect unchanged)
Cite:
mesh-connectivity-daemon-design-2026-10-02.md§1.2 / §1.5 / tips 5–6mesh-underlay-linux-tun-wg-vs-win-mac-2026-10-02.md- hatchery
mesh_roleDialOnly lock
Feature: mesh-underlay (default on). Disable to omit this module from
dependents that do not need tip-5/6 surfaces.
Structs§
- Bridge
Underlay Client - Client-side stream: HTTP+WS bytes in, framed underlay out (tip 6).
- Linux
Underlay Listener - Listener side (C2 or node accept-peer).
- Linux
Underlay Session - Established encrypted underlay session (either dial or accept side).
- TunSurface
Report - Informational TUN/CAP report — not required for the UDP+AEAD path.
- Underlay
Auth Token - Authorization token barrier inside the encrypted underlay path.
Distinct from
UnderlayTransportKey. Never logged. - Underlay
Transport Key - 32-byte transport key for underlay AEAD (encrypts the pipe — not auth).
Enums§
- Mesh
Underlay Dial Capability - Dial capability derived from role.
- Mesh
Underlay Error - Errors for the tip-5 underlay slice (never carry token material).
- Mesh
Underlay Role - Who participates on the underlay (mirrors hatchery
MeshParticipantRole).
Functions§
- accept_
peer - accept_
peer_ on - Tip 6: underlay UDP accept on an explicit bind (may be non-loopback for
mesh peers). Application HTTP+WS stays on loopback
--bridge-listen; this only accepts the encrypted underlay path. HQ DialOnly still refused. - assert_
accept_ allowed - Refuse underlay accept when role is dial-only (HQ).
- authorize_
probe - Check authorization for a probe action. Encrypted path being up is irrelevant.
- dial_
peer - open_
wireguard_ daemon_ stub - Explicit refuse of full WG daemon product this tip.
- probe_
tun_ surface - serve_
bridge_ tcp_ relay - Server side: wait for OPEN+token, authorize underlay token, dial local
--bridge-listen, relay until close. HQ must never call this (accept refused upstream). Application BRIDGE_TOKEN remains a separate barrier. - tokens_
match - Constant-time equality for token barriers (spirit of C2/bridge gates).
- underlay_
to_ io - Map underlay path errors that look like I/O into std::io::Error for node loops.